CVE-2018-11886

HIGH

Android - Integer Overflow and Buffer Overflow in WLAN MPDU Length Calculation

Title source: llm
STIX 2.1

Description

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check while calculating the MPDU data length will cause an integer overflow and then to buffer overflow in WLAN function.

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
google/android
Published Sep 19, 2018
Tracked Since Feb 18, 2026